AI at X: Privacy Concerns, GDPR Violations, and Misinformation

Martin Bastius
08.11.2024
999
min.

The rise and rapid development of AI technologies bring significant benefits, such as an improved user experience and functionality on platforms like X, Instagram, or Facebook. However, they also raise pressing questions about data protection practices, particularly regarding the collection and use of personal data without informed consent.

Furthermore, the possibility that AI models could spread misinformation is cause for concern among the hundreds of millions of users actively using platforms like X, since this could potentially influence the course of human events.

In this article, we take a closer look at X's current AI model training practices, as well as the potential implications for data protection and the spread of misinformation.

Understanding Grok, X's AI Model

X's AI model, Grok, is a large language model (LLM) designed to process and generate human-like text based on vast datasets. It can interpret user intent and context, resulting in more meaningful interactions, and continuously learns from ongoing user interaction, which improves its responses over time. Grok was designed as an AI search assistant for premium account holders on X and was developed by Musk's US company, xAI Corp.

The training method for LLMs like Grok relies heavily on user-generated content, particularly from X. Grok is trained on millions of posts, comments, and interactions within the platform. By analyzing this data, Grok identifies trends, sentiments, and linguistic nuances that feed into its responses.

User posts therefore play a decisive role in shaping the behavior and performance of AI models like Grok. They provide the fundamental context from which the model learns about various topics and user preferences.

And this reliance on personal content raises significant data protection concerns under the GDPR.

Possible GDPR Violations in the AI Training Model

In August 2024, noyb — European Center for Digital Rights, a nonprofit organization supporting GDPR enforcement, filed a complaint with nine GDPR supervisory authorities in Ireland, Austria, Belgium, France, Greece, Italy, the Netherlands, Spain, and Poland, alleging that X had unlawfully used the personal data of more than 60 million users in the EU/EEA — without their consent — to train its AI technologies (such as “Grok”).

The complaint laid out the following facts: in September 2023, X added this sentence to its privacy policy

“We may use the information we collect and publicly available information to train our machine learning or artificial intelligence models for the purposes outlined in this policy.”

According to noyb, X began training its AI model on posts from users based in the EU starting in May 2024, without further notifying them or asking for their consent.

In July 2024, X also added a new setting to its web interface that allows interactions on the platform to be used for training its AI model. This setting was enabled by default. The data can even be shared with xAI, a separate company led by Elon Musk that develops artificial intelligence, including but not limited to Grok.

x and ai.webp

The complaint also explains how opting out of this data sharing violates users' “right to object” under Article 21 of the GDPR, since users have to complete seven steps before they can disable the setting — including logging into X, navigating through the settings menu, and opening several submenus before they can turn off data sharing.

Overall, noyb claims that X's actions violate multiple provisions of the GDPR, including its core principles, transparency rules, and operational rules.

Legal Proceedings and Future Implications

In August 2024, the Irish Data Protection Commission (DPC) initiated proceedings against Twitter International Unlimited Company, X's main Irish subsidiary, before the High Court of Ireland. The proceedings concerned the use of X users' personal data to train Grok, X's AI model.

As a result, X agreed to suspend processing of the personal data collected between May and August 2024. The proceedings were then discontinued in September 2024, after X agreed to permanently stop processing certain personal data.

So far, X has managed to avoid sanctions, although further GDPR-related complaints concerning Grok's training are still under investigation.

The case exposed a potential loophole: once an LLM has been trained on personal data, reversing the AI training process is difficult or impossible, making it hard for data subjects to exercise their right to erasure under the GDPR. This prompted the data protection authority to petition the European Data Protection Board (EDPB) for a “proactive, effective, and harmonized EU-wide framework” for AI companies that use social media posts to train their models.

X's Response and Data Protection Concerns

On August 7, 2024, X's Global Government Affairs team posted:

“The order sought by the Irish Data Protection Authority is unjustified, excessive, and singles out X without cause. This is deeply concerning ... While many companies continue to scrape the internet to train AI models without regard for user privacy, X has done everything in its power to give users more control over their data.”

This response raises further concerns about whether data protection and user privacy are truly a priority for the platform, as well as doubts about its ability to address issues like hate speech, misinformation, and user safety. In June 2023, X received legal notices from the Australian government demanding explanations of its hate speech policies. Later that year, X came under pressure to comply with the European Union's strict Digital Services Act, particularly regarding its rules for handling misinformation.

See also: Understanding the EU's Digital Services Act: A Guide for Businesses

Elon Musk's Leadership and Misinformation

Concerns about data protection and misinformation have grown since Elon Musk's acquisition of Twitter for $44 billion in 2022. The new leadership style has led to more aggressive monetization strategies that often prioritize rapid growth over protecting user privacy, raising concerns about how personal data is handled.

Moreover, Musk himself — the most-followed user on X, with more than 200 million followers — has done little to improve X's perception as a well-regulated platform, and often contributes to misinformation himself. Musk has shared a wide range of misinformation on X; here are a few examples:

  • In 2020, as the US imposed lockdowns to curb the spread of Covid, Musk made a bold prediction on Twitter: "Based on current trends, probably close to zero new cases in [the] US too by end of April" and even claimed children were "essentially immune" to Covid
  • In 2023, Musk settled fraud allegations with the Securities and Exchange Commission by agreeing to a $20 million fine over a misleading comment that “caused significant market disruption.”
  • In 2024, X's CEO — an enthusiastic supporter of Donald Trump in the upcoming US presidential election — shared 50 misleading or false tweets about the US elections, according to the Center for Countering Digital Hate, which were viewed a combined total of over 1.2 billion times. This included sharing a deepfake video of Democratic candidate Kamala Harris without disclosing that it was manipulated. In the manipulated video, Harris declares: “I am the ultimate person of diversity.”
  • Additionally, in September 2024, X laid off the safety team responsible for combating fraudulent material on the platform, shortly before the US presidential election in November 2024.
  • In August 2024, five secretaries of state sent an open letter to Musk demanding he make “immediate” changes to Grok, X's AI chatbot, which had spread false claims that Harris had missed a ballot deadline in nine states — misinformation seen by millions of users.

Musk's public behavior has contributed to ethical concerns and user skepticism about X's ability to manage information responsibly and maintain safe practices.

Conclusion

With over 430 million users worldwide, X's influence and reach have become a cause for concern. The platform's role in spreading misinformation, its lack of transparency regarding manipulated content, and its disregard for data protection and transparency have raised questions about its commitment to ethical practices.

In summary, X faces major challenges in addressing data protection concerns and misinformation on its platform. The potential GDPR violations related to its AI model training process underscore the need for stricter compliance measures to protect user data.

Elon Musk's leadership has brought both innovation and controversy, with his handling of misinformation and data protection issues drawing widespread criticism.

To rebuild trust, X must prioritize transparency, strengthen its data protection policies, and ensure the ethical use of AI technologies.

This is where heyData comes in: with our innovative AI Solution, we help you meet the requirements of the EU AI Act, master data protection requirements, and uphold ethical standards in the use of AI. Our tailored compliance roadmaps and automated documentation make it easy for you to implement complex requirements. Learn more in our whitepaper.

Published
08.11.2024
Martin Bastius
Co-Founder & CLO

More articles

View all articles
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
AI & Data Governance
7/11/25

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant

Balancing Trust and Control: How to Make AI-Recorded Online Meetings GDPR-Compliant
AI & Data Governance
6/12/26

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection

Whistleblower System for SMBs: What You Need to Know About Whistleblower Protection
Discover all stories